Our Network Team spotted that when Veeam Backups are running, there are very VERY large volumes of traffic for a single Verisign CRL file.
In a day they have seen 221GB of data flow from Element servers etc. to the Verisign URL:
http://crl3.digicert.com/DigiCertGlobal ... 0CA1-1.crl
This URL seems to only be accessed frequently by Veeam clients - other devices seem to download it and cache it.
Disabling the CRL checks is not something which we’d like to do if at all possible.
Is there another way in which the above can be remediated so that the required CRL is downloaded and cached, rather than the current scenario as it seems closely tied to the Veeam/Wasabi traffic flows.
This issue was originally raised via Support - Case # 08161556 and I was informed that at present there is nothing to mitigate this issue, so I was advised to open a Feature Request via the R&D Forum
-
paul.jones
- Lurker
- Posts: 2
- Liked: never
- Joined: Jul 20, 2026 8:05 am
- Full Name: Paul Jones
- Contact:
-
vnikiforov
- Veeam Software
- Posts: 150
- Liked: 53 times
- Joined: Aug 17, 2022 5:03 am
- Full Name: Vladimir Nikiforov
- Location: Romania
- Contact:
Re: Veeam B&R v12.* CRL Caching Feature Request
Hello, Paul,
The traffic pattern you see is how v12 performs certificate revocation checks for object storage.
Veeam Backup & Replication v12 has passed its End of Fix milestone in November 2025 under the Veeam product lifecycle policy, so this behavior will not change in any 12.x build.
A feature request is not needed as well: V13 reworked the revocation workflow, and certificate revocation is now checked via OCSP queries, so there are no more such traffic patterns, as in previous versions.
The only workaround if the issue is critical for your infrastructure is disabling revocation check for object storage via registry key. I would also recommend you consider upgrading to Veeam Backup & Replication v13.
The traffic pattern you see is how v12 performs certificate revocation checks for object storage.
Veeam Backup & Replication v12 has passed its End of Fix milestone in November 2025 under the Veeam product lifecycle policy, so this behavior will not change in any 12.x build.
A feature request is not needed as well: V13 reworked the revocation workflow, and certificate revocation is now checked via OCSP queries, so there are no more such traffic patterns, as in previous versions.
The only workaround if the issue is critical for your infrastructure is disabling revocation check for object storage via registry key. I would also recommend you consider upgrading to Veeam Backup & Replication v13.
---
BR,
Vladimir
Veeam Software
BR,
Vladimir
Veeam Software
-
paul.jones
- Lurker
- Posts: 2
- Liked: never
- Joined: Jul 20, 2026 8:05 am
- Full Name: Paul Jones
- Contact:
Re: Veeam B&R v12.* CRL Caching Feature Request
Hi vnikiforov,
Many Thanks for responding and providing the information regarding this feature request/issue.
Much appreciated.
Paul
Many Thanks for responding and providing the information regarding this feature request/issue.
Much appreciated.
Paul
Who is online
Users browsing this forum: Google [Bot], Semrush [Bot] and 329 guests